Vulnerabilities (CVE)

Filtered by vendor Extremenetworks Subscribe
Filtered by product Extremexos
Total 8 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18305 1 Extremenetworks 1 Extremexos 2025-06-11 N/A 8.0 HIGH
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.
CVE-2024-27453 1 Extremenetworks 1 Extremexos 2025-06-10 N/A 8.6 HIGH
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
CVE-2017-14327 1 Extremenetworks 1 Extremexos 2025-04-20 4.9 MEDIUM 4.4 MEDIUM
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files.
CVE-2017-14332 1 Extremenetworks 1 Extremexos 2025-04-20 6.8 MEDIUM 8.1 HIGH
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.
CVE-2017-14331 1 Extremenetworks 1 Extremexos 2025-04-20 7.2 HIGH 6.7 MEDIUM
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.
CVE-2017-14329 1 Extremenetworks 1 Extremexos 2025-04-20 7.2 HIGH 6.7 MEDIUM
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.
CVE-2017-14328 1 Extremenetworks 1 Extremexos 2025-04-20 7.8 HIGH 7.5 HIGH
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.
CVE-2017-14330 1 Extremenetworks 1 Extremexos 2025-04-20 7.2 HIGH 6.7 MEDIUM
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.